You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

解决GitLab搭配Drone Runner时DRONE_RUNNER_CAPACITY>1的OAuth错误

问题

使用Drone server(2.17版本)、Docker Runner(1.8版本)与GitLab(16.0版本)集成,配置如下:

services:
  drone:
    image: drone/drone:2.17
    container_name: drone-srv
    restart: always
    ports:
      - "5100:80"
    volumes:
      - /var/lib/drone:/data
    environment:
      DRONE_GITLAB_SERVER: <server>
      DRONE_GITLAB_CLIENT_ID: <client_id>
      DRONE_GITLAB_CLIENT_SECRET: <secret>
      DRONE_GITLAB_SKIP_VERIFY: "true"
      DRONE_RPC_SECRET: <secret>
      DRONE_SERVER_HOST: <host>
      DRONE_SERVER_PROTO: https
      DRONE_USER_CREATE: username:admin,admin:true
      DOCKER_API_VERSION: 1.39
  runner:
    image: drone/drone-runner-docker:1.8
    container_name: drone-runner
    restart: always
    ports:
      - "5110:3000"
    volumes:
      - /var/run/docker.sock:/var/run/docker.sock
    environment:
      DRONE_RPC_PROTO: https
      DRONE_RPC_HOST: <host>
      DRONE_RPC_SECRET: <secret>
      DRONE_RUNNER_CAPACITY: 5
      DRONE_RUNNER_NAME: drone-docker-runner-1
      DRONE_RUNNER_ENVIRON: GIT_SSL_NO_VERIFY:false     

当DRONE_RUNNER_CAPACITY>1(示例中设为5)时,Runner出现GitLab OAuth流程失败,流水线停滞,日志频繁出现错误:

time="2023-06-20T07:27:05Z" level=error msg="cannot get stage details" error="The provided authorization grant is invalid, expired, revoked, does not match the redirection URI used in the authorization request, or was issued to another client." stage.id=7170 stage.name="..." stage.number=1 thread=5

推测多线程复用同一授权凭证导致互相干扰,仅单线程能正常工作,需实现多流水线并行运行。

解决方案

1. 升级Drone Runner版本

Drone Docker Runner 1.8版本存在多线程下的OAuth凭证复用冲突问题,官方在1.9.0及以上版本中修复了该类并发场景的Bug,直接升级Runner镜像版本即可解决问题。

2. 配置全局Git凭证(临时替代方案)

若暂时无法升级版本,可为Runner配置全局Git凭证,绕过流水线的临时OAuth授权:

  • 在Runner的环境变量中添加:
    DRONE_GIT_USERNAME: <你的GitLab用户名>
    DRONE_GIT_PASSWORD: <你的GitLab个人访问令牌>
    
    个人访问令牌需具备read_repository权限。
  • 确保流水线.drone.yml中未配置OAuth相关逻辑,直接使用全局凭证拉取代码。

3. 拆分多Runner实例

将单Runner的DRONE_RUNNER_CAPACITY设为1,同时启动多个独立的Runner容器,每个Runner单独处理任务,避免线程间凭证冲突:

  • 复制原Runner配置,修改容器名称和Runner名称,示例如下:
    runner-2:
      image: drone/drone-runner-docker:1.8
      container_name: drone-runner-2
      restart: always
      volumes:
        - /var/run/docker.sock:/var/run/docker.sock
      environment:
        DRONE_RPC_PROTO: https
        DRONE_RPC_HOST: <host>
        DRONE_RPC_SECRET: <secret>
        DRONE_RUNNER_CAPACITY: 1
        DRONE_RUNNER_NAME: drone-docker-runner-2
        DRONE_RUNNER_ENVIRON: GIT_SSL_NO_VERIFY:false     
    
  • 根据需要启动多个此类Runner实例,总并行数等于Runner实例数量。

内容的提问来源于stack exchange,提问作者Roman Bobrik

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.07.17 21:15:13